Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 10.0
CVE-2025-63216
The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse…
Idgateway Firmware
Mitigation only
HIGH 7.5
CVE-2024-21635
Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their passw…
Memos
after 0.18.1
CRITICAL 9.8
CVE-2025-64717
ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability i…
Zitadel
2.71.19 / 3.4.4+
HIGH 8.2
CVE-2025-12998
Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modules.This issue affects Extension "Modules": before 4.3.11, from 5.0.0…
Mitigation only
CRITICAL 9.3
CVE-2025-64513
Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a vulnerability in versions pr…
Patch available
MEDIUM 6.3
CVE-2025-64434
KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via ver…
Kubevirt
1.5.3+
CRITICAL 9.3
CVE-2025-3222
Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and…
Mitigation only
MEDIUM 6.7
CVE-2025-20730
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a mal…
Yocto
Mitigation only
CRITICAL 9.8
CVE-2025-64103
Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or…
Zitadel
2.71.18 / 3.4.3+
HIGH 7.6
CVE-2025-60424
A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a brut…
Fusion
Mitigation only
CRITICAL 9.1
CVE-2025-62717
Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing lo…
Emlog
Patch available
CRITICAL 9.8
CVE-2025-43995
Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with…
Storage Manager
2020+
HIGH 8.8
CVE-2025-6979
Captive Portal can allow authentication bypass
No fix yet
HIGH 8.1
CVE-2025-62169
OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions…
Patch available
MEDIUM 5.4
CVE-2025-62398
A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially co…
Moodle
4.4.11 / 4.5.7+
CRITICAL 9.8
CVE-2025-56447
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
Mitigation only
CRITICAL 9.8
CVE-2025-41108
The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external att…
Vision 60 Firmware
Mitigation only
HIGH 8.8
CVE-2025-41110
Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the ro…
Vision 60 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-60772
Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to escalate …
Mitigation only
CRITICAL 9.8
CVE-2025-11625
Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients cre…
Wolfssh
after 1.4.20
CRITICAL 9.8
CVE-2025-11942
A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing manipulation can lead to miss…
X200 Firmware
after 2025-10-10
MEDIUM 5.3
CVE-2025-11852
A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/device_service of the compone…
Mitigation only
CRITICAL 9.1
CVE-2025-61922
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5…
Prestashop Checkout
7.4.4.1 / 7.5.0.5+
HIGH 7.8
CVE-2025-43281
The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privil…
macOS
15.6+
HIGH 8.8
CVE-2025-10293
The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,…
Mitigation only
CRITICAL 9.5
CVE-2025-62376
pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef, the /workspace endpoi…
Patch available
HIGH 7.0
CVE-2025-55340
Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.
Windows 10 21h2
10.0.19044.6456 / 10.0.19045.6456+
MEDIUM 6.5
CVE-2025-53845
An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated a…
Fortianalyzer
7.4.7 / 7.6.4+
CRITICAL 9.8
CVE-2025-9063
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerabili…
Factorytalk View
after 15.0
CRITICAL 9.1
CVE-2025-9064
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device …
Factorytalk View
after 15.0